Skip to content
Security Trust Centre

Everything you need to know about how we secure the platform โ€” and how you can verify it.

AravaliStack is built for regulated environments. This page documents our security posture, certifications, and how we respond to vulnerabilities.

Certifications & Compliance

Where we stand today.

We operate a responsible disclosure programme. If you find a security vulnerability in AravaliStack, we want to hear from you โ€” and we commit to acknowledging your report within 48 hours.

  • Zero Trust at Layer 1

    Security is not a layer we add to the top of the platform. It is the architectural substrate โ€” every component is designed with zero trust as a non-negotiable constraint.

  • Policy as Auditable Code

    Every security policy is a version-controlled document. Auditors can review the history of every security decision, who approved it, and when it took effect.

  • No Long-Lived Credentials

    Machine identities are short-lived and rotated automatically. No static API keys. No long-lived service account passwords. Every credential has a defined expiry.

  • Report to: hello@aravalistack.com (GPG key available)
  • Acknowledgement within 48 hours
  • Patch release timeline communicated within 7 days
  • Researcher credited in security advisory (if desired)
  • We commit to no legal action against good-faith researchers
  • Certification Ready
  • Information security management system aligned to ISO 27001 requirements. Audit evidence available for enterprise customers.
  • Architecture Aligned
  • Platform architecture designed to meet PCI-DSS v4.0 requirements for cardholder data environments. Network segmentation and access controls pre-built.
  • Capability Certified
  • Technical, administrative, and physical safeguards aligned to HIPAA requirements. Business Associate Agreement available.
  • DPDP Act 2023
  • Platform designed for full compliance with India's Digital Personal Data Protection Act โ€” data residency, consent management, and audit trail requirements.
  • Independent Security Testing
  • AravaliStack conducts annual third-party penetration testing across all platform components. Results are summarised and available under NDA to enterprise prospects. Our last test was conducted in Q4 2025 by a CERT-IN empanelled security firm. No critical findings were unresolved at the time of platform release.
  • How We Handle Vulnerabilities
  • Our Security Architecture Principles

Security questions? We answer them directly.

Talk to our security team โ€” not a questionnaire portal.